Vulnerability assessment is the systematic process of identifying, analyzing, and prioritizing weaknesses in systems and applications.
Vulnerability Databases
- CVE (Common Vulnerabilities and Exposures): Official list of disclosed vulnerabilities
- NVD (National Vulnerability Database): NIST's database with CVSS scores
- CVSS (Common Vulnerability Scoring System): Standardized scoring 0-10
Assessment Process
- Scanning: Automated tools (Nessus, OpenVAS) identify vulnerabilities
- Verification: Manual confirmation of findings
- Analysis: Determine impact and affected systems
- Prioritization: Risk-based triage using CVSS
- Remediation: Patching or workarounds
- Retesting: Verify fixes
Popular Tools
- Nessus: Industry-standard vulnerability scanner
- OpenVAS: Open-source vulnerability scanner
- Qualys: Cloud-based scanning
- Quick7: Comprehensive assessment platform